From 45f62bdedda425d323c8a1b926503edd02df1681 Mon Sep 17 00:00:00 2001 From: matt335672 <30179339+matt335672@users.noreply.github.com> Date: Wed, 11 Mar 2026 15:55:04 +0000 Subject: [PATCH] CVE-2026-33145: Default AllowAlternateShell to 'no' --- docs/man/sesman.ini.5.in | 3 ++- sesman/libsesman/sesman_config.c | 2 +- sesman/sesman.ini.in | 4 ++-- 3 files changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/man/sesman.ini.5.in b/docs/man/sesman.ini.5.in index eda5d01b..9e38e061 100644 --- a/docs/man/sesman.ini.5.in +++ b/docs/man/sesman.ini.5.in @@ -365,7 +365,8 @@ because the system is unable to check whether the user is an administrator. .TP \fBAllowAlternateShell\fR=\fI[true|false]\fR -If set to \fB0\fR, \fBfalse\fR or \fBno\fR, prevent usage of alternate shells by users. +Set to \fB1\fR, \fBtrue\fR or \fByes\fR, to allow alternate shells to +be specified by users. .TP \fBPassShellAsEnv\fR=\fI\fR diff --git a/sesman/libsesman/sesman_config.c b/sesman/libsesman/sesman_config.c index 215aa2da..3c422549 100644 --- a/sesman/libsesman/sesman_config.c +++ b/sesman/libsesman/sesman_config.c @@ -320,7 +320,7 @@ config_read_security(int file, struct config_security *sc, sc->xauth_in_sysdir = 0; sc->restrict_outbound_clipboard = 0; sc->restrict_inbound_clipboard = 0; - sc->allow_alternate_shell = 1; + sc->allow_alternate_shell = 0; sc->pass_shell_as_env = g_strdup(""); sc->xorg_no_new_privileges = 1; sc->ts_users = g_strdup(""); diff --git a/sesman/sesman.ini.in b/sesman/sesman.ini.in index 96ead6b6..098d1ca0 100644 --- a/sesman/sesman.ini.in +++ b/sesman/sesman.ini.in @@ -43,8 +43,8 @@ RestrictOutboundClipboard=none ; false: an alias of none ; yes: an alias of all RestrictInboundClipboard=none -; Set to 'no' to prevent users from logging in with alternate shells -#AllowAlternateShell=true +; Set to 'yes' to allow users to log in with alternate shells +#AllowAlternateShell=no ; Normally, alternate shells (if permitted) are executed directly, as ; specified. ; If this is set, alternate shells are not actioned directly, but